Massive automated vulnerability scan and web shell hunting campaign. The actor is probing for a vast ...
show moreMassive automated vulnerability scan and web shell hunting campaign. The actor is probing for a vast array of backdoor scripts, including known shells (bolt.php, t00l.php, karma_b001.php) and hundreds of randomized 5-letter PHP filenames. The attack targets multiple subdomains (www, cpcalendars) with extreme velocity (100+ requests in a few seconds), indicating a highly coordinated effort to locate unauthorized file upload vulnerabilities.
show less
Automated vulnerability scanning and forum software probing. The actor is performing high-frequency ...
show moreAutomated vulnerability scanning and forum software probing. The actor is performing high-frequency requests against viewforum.php, likely searching for unpatched forum software (phpBB/vBulletin) to exploit for SQL injection or automated spam registration. High-velocity burst pattern indicates non-human, automated reconnaissance.
show less
Aggressive automated credential harvesting and secret probing. The actor is systematically targeting ...
show moreAggressive automated credential harvesting and secret probing. The actor is systematically targeting the /.env path across dozens of subdomains in a high-velocity burst. This is a targeted attempt to locate environment files containing sensitive API keys, database credentials, and system secrets. Originates from a known hosting provider (PFCloud/Intelligence Hosting) frequently associated with malicious scanning.
show less
Automated subdomain enumeration and infrastructure reconnaissance originating from Lumen (AS209). Ac ...
show moreAutomated subdomain enumeration and infrastructure reconnaissance originating from Lumen (AS209). Actor is executing simultaneous requests across a wide variety of common service subdomains (webmail, cpcontacts, autodiscover, webdisk, etc.) to map the target's attack surface. High-concurrency burst indicates non-human, automated probing.
show less
Persistent automated WordPress reconnaissance and directory fuzzing. The actor is performing high-ve ...
show morePersistent automated WordPress reconnaissance and directory fuzzing. The actor is performing high-velocity scans for wlwmanifest.xml across numerous directory aliases (e.g., /sito/, /cms/, /wordpress/, /test/) and probing xmlrpc.php for potential exploitation. The use of double-slashes in the URI path indicates an attempt to bypass security filters or exploit misconfigured path handling.
show less
Aggressive automated web scraping and crawling originating from Liquid Web. Actor is executing high- ...
show moreAggressive automated web scraping and crawling originating from Liquid Web. Actor is executing high-frequency requests across dozens of content pages, tags, and category structures within a 10-second window. The bot ignores standard crawl delays and is performing deep site enumeration.
show less
Automated vulnerability scanning and backdoor probing originating from Microsoft Azure. The actor is ...
show moreAutomated vulnerability scanning and backdoor probing originating from Microsoft Azure. The actor is systematically hunting for specialized web shells (gu.php, rafa.php, 34.php, js.php) with a heavy focus on obfuscated paths like /.well-known/pki-validation/ and specific WordPress themes/plugins (pridmag, hellopress). This high-velocity burst (24 requests in 1 second) indicates a coordinated exploit attempt.
show less
Automated subdomain enumeration and infrastructure reconnaissance originating from DigitalOcean. Act ...
show moreAutomated subdomain enumeration and infrastructure reconnaissance originating from DigitalOcean. Actor is rapid-firing requests across a wide range of common subdomain prefixes (e.g., autodiscover, webdisk, cpanel, forum, home) in a single second. This high-velocity probing is used to map out the attack surface for targeted vulnerability exploitation.
show less
Aggressive automated credential harvesting and sensitive information disclosure probing originating ...
show moreAggressive automated credential harvesting and sensitive information disclosure probing originating from IONOS (Germany). The actor is systematically targeting both the root and www domains for configuration files containing secrets, including .env.bak, .aws/credentials, aws.yml, and various phpinfo paths. This is a targeted effort to hijack cloud infrastructure and database credentials.
Observed Activity:
Secret Harvesting: Probing for environment and AWS credential files: /.env.bak, /.aws/credentials, and /config/aws.yml.
System Fingerprinting: Multiple attempts to access phpinfo and _profiler/phpinfo to identify server versions and loaded modules.
Method: High-frequency IPv6 automated scanning (30+ requests in 20 seconds).
User Agent: Using a spoofed, misspelled Android user agent ("Mozlila" instead of "Mozilla") to bypass basic filters.
show less
Coordinated automated vulnerability scanning and backdoor probing from Microsoft Azure. The actor is ...
show moreCoordinated automated vulnerability scanning and backdoor probing from Microsoft Azure. The actor is targeting the root domain to locate specific web shells (bolt.php, ioxi-o.php, fff.php) and is probing WordPress-specific directories for unauthorized execution points. This activity matches a widespread campaign observed across multiple subdomains today.
Observed Activity:
Web Shell Hunting: Searching for known malicious files: /ioxi-o.php, /fff.php, /as.php, and /xmr.php.
Targeted WP Exploitation: Probing for a shell hidden in the CSS directory: /wp-admin/css/bolt.php.
Directory Reconnaissance: Scanning for open directories or scripts in /wp-content/uploads/ and /wp-includes/.
Method: High-speed automated burst (12 requests in a single second).
show less
Automated vulnerability scanning and exploit probing originating from a Microsoft Azure node (Singap ...
show moreAutomated vulnerability scanning and exploit probing originating from a Microsoft Azure node (Singapore). The actor is systematically targeting the mail subdomain to identify misconfigured WordPress directories and hunting for specialized web shells like bolt.php, ioxi-o.php, and da222.php. The scan includes attempts to execute scripts in hidden/obfuscated paths like /.trash7206/ and /.well-known/logs233/.
Observed Activity:
Backdoor Hunting: Probing for specialized malicious scripts: /wp-admin/css/bolt.php, /rip.php, /ioxi-o.php, and /xmr.php.
Obfuscated Path Discovery: Systematic attempts to hit hidden directories: /.trash7206/index.php and /.well-known/logs233/index.php.
Administrative Probe: Targeting WordPress core execution points: /wp-act.php, /update/da222.php, and /adminfuns.php.
Method: High-velocity automated burst (37 unique paths hit within 6 seconds).
show less
Aggressive vulnerability scanning and backdoor hunting originating from Microsoft Azure. The actor i ...
show moreAggressive vulnerability scanning and backdoor hunting originating from Microsoft Azure. The actor is probing the autodiscover subdomain for specialized web shells (bolt.php, ff1.php, rip.php) and "hidden" directory execution points in /.trash7206/ and /.well-known/logs233/.
Observed Activity:
Specific Shell Hunting: Searching for bolt.php in the CSS directory and ff1.php in the root.
Hidden Directory Probing: Attempting to find scripts in obfuscated paths: /.well-known/logs233/index.php and /.trash7206/index.php.
WP Core Probing: Scanning for adminfuns.php and wp-act.php.
Method: Automated high-speed burst (17 requests in a single second).
Intent: Remote Code Execution (RCE) and persistence via pre-installed backdoors.
show less
High-velocity vulnerability scanning and backdoor hunting originating from Microsoft Azure. The acto ...
show moreHigh-velocity vulnerability scanning and backdoor hunting originating from Microsoft Azure. The actor is systematically probing the webmail subdomain for malicious PHP scripts and hunting for "forgotten" vulnerabilities in non-standard directories like /.trash7206/.
Observed Activity:
Backdoor Hunting: Probing for malicious scripts: /wp-act.php, /update/da222.php, and /inputs.php.
Administrative Reconnaissance: Targeting sensitive WordPress paths: /wp-admin/maint/, /wp-admin/js/widgets/, and /wp-content/uploads/admin.php.
Trash/Backup Probing: Attempting to locate execution points in hidden or temporary directories: /.trash7206/index.php.
Method: Automated burst (14 requests in a single second).
Intent: Remote Code Execution (RCE) and identification of existing server compromises.
show less
Persistent automated WordPress reconnaissance and directory fuzzing originating from Clouvider (ASN ...
show morePersistent automated WordPress reconnaissance and directory fuzzing originating from Clouvider (ASN 62240). The actor is performing repetitive, high-velocity scans for wlwmanifest.xml across dozens of common directory aliases (e.g., /sito/, /cms/, /shop/, /wp1/, /wp2/, /test/). This activity is a textbook case of environment fingerprinting to identify vulnerable hidden WordPress installations for future exploitation. Activity was observed spanning several hours (1:25 AM and 4:52 PM), indicating a scheduled or persistent scanning task.
Observed Activity:
Path Discovery: Exhaustive probing for wlwmanifest.xml in common subdirectories.
Service Reconnaissance: Targeting xmlrpc.php for potential brute-force or DDoS amplification vectors.
Multi-Domain Targeting: Probing www, cpanel, and webdisk subdomains.
Frequency: Automated bursts of 20+ requests within a 2-second window.
show less
Automated WordPress reconnaissance and directory fuzzing. The actor is systematically probing dozens ...
show moreAutomated WordPress reconnaissance and directory fuzzing. The actor is systematically probing dozens of common subdirectory paths (e.g., /cms/, /shop/, /test/, /blog/) specifically looking for wlwmanifest.xml and xmlrpc.php. This is a classic fingerprinting technique used to identify vulnerable WordPress installations and versioning for subsequent targeted exploitation.
Observed Activity:
Path Fuzzing: Rapid-fire requests for wlwmanifest.xml across 15+ different directory variants.
Service Probing: Attempting to access xmlrpc.php for potential brute-force or DDoS amplification.
Method: High-velocity automated scanning (20+ requests in 2 seconds).
Target: Multiple subdomains including www and cpcalendars.
show less
Aggressive automated vulnerability scanning originating from a Microsoft Azure node. The actor is pe ...
show moreAggressive automated vulnerability scanning originating from a Microsoft Azure node. The actor is performing high-velocity probing for critical WordPress vulnerabilities and malicious PHP backdoors on the cpcontacts subdomain.
Observed Activity:
File Manager Exploitation: Targeting known vulnerabilities in file management plugins: /wp-content/plugins/hellopress/wp_filemanager.php and /filemanager.php.
SMTP Hijacking: Attempting to locate scripts to turn the server into a spam relay: /makeasmtp.php.
Web Shell Hunting: Probing for specialized shells: /alfanew.php, /xl2023.php, and several randomized-name PHP files (e.g., /twlsgobh.php, /9FM3suPlwtZ.php).
Configuration Theft: Hunting for typosquatted config files like /wp-conflg.php.
Method: High-concurrency burst (21 requests within the same second), characteristic of an automated exploit kit.
show less
Automated vulnerability scanning and backdoor probing detected. The actor is systematically targetin ...
show moreAutomated vulnerability scanning and backdoor probing detected. The actor is systematically targeting the root domain to locate known web shells and exploit WordPress-specific administrative files and directories.
Observed Activity:
Backdoor Hunting: Probing for malicious scripts: /ws.php, /sf.php, /wp-good.php, and /chosen.php.
WordPress Exploitation: Systematic scanning of /wp-admin/user/index.php, /wp-trackback.php, and the /wp-includes/PHPMailer/ directory.
Infrastructure Reconnaissance: Targeting non-standard files like /autoload_classmap.php, /adminfuns.php, and /class-t.api.php to identify potential remote code execution (RCE) entry points.
Method: High-frequency automated HTTP GET requests (16+ requests within a single second), indicative of a botnet-driven exploit scanner.
Intent: Identifying vulnerabilities or existing server compromises to facilitate unauthorized access.
show less
Persistent and high-velocity automated vulnerability scanning originating from a Microsoft Azure nod ...
show morePersistent and high-velocity automated vulnerability scanning originating from a Microsoft Azure node (South Korea). The actor is performing an exhaustive "shotgun" style scan against the mail subdomain, searching for a wide variety of known PHP backdoors, web shells, and WordPress configuration vulnerabilities. Observed Activity:Exploit Hunting: Targeted probing for specific malicious files: /wsoyanz.php, /randkeyword.PhP7, /ioxi-o.php, /rip.php, /xleet, and /kbfr.php. WordPress Core Tampering: Probing for unauthorized scripts in administrative and core directories: /wp-content/themes/hideo/network.php, /wp-admin/css/colors/ectoplasm/, /wp-conf.php, and /wp-good.php.
Mail Infrastructure Targeting: Probing /wp-includes/PHPMailer/ and /xmlrpc.php, likely seeking to exploit mail-handling vulnerabilities for spam or relay purposes.
Method: Mass-scale automated HTTP GET requests (50+ unique paths hit within a 3-second window), clearly indicating a sophisticated exploit bot.
Intent: Remote Code Execution
show less
Automated vulnerability scanning and exploit probing originating from a Microsoft Azure IP. The acto ...
show moreAutomated vulnerability scanning and exploit probing originating from a Microsoft Azure IP. The actor is systematically targeting the cpanel subdomain to identify misconfigured WordPress directories and hunt for known web shell backdoors.
Observed Activity:
Backdoor Hunting: Probing for malicious scripts such as /rip.php and /abcd.php.
WordPress Core Probing: Scanning for sensitive directories and execution points: /wp-includes/PHPMailer/, /xmlrpc.php, and misspelled variants like /xmrlpc.php.
Infrastructure Reconnaissance: Targeting non-standard paths like /wk/index.php and looking for scripts within specific theme CSS directories (/wp-admin/css/colors/ectoplasm/).
Method: High-frequency automated HTTP GET requests (14 requests in a single second), indicative of a bot-driven security scanner.
Intent: Identifying Remote Code Execution (RCE) vulnerabilities or existing server compromises.
show less
Aggressive automated vulnerability scanning and backdoor hunting originating from a Microsoft Azure ...
show moreAggressive automated vulnerability scanning and backdoor hunting originating from a Microsoft Azure IP. The actor is systematically probing the cpcontacts subdomain for multiple known web shells and malicious PHP scripts, targeting both WordPress core directories and obscure administrative paths.
Observed Activity:
Web Shell Probing: Multiple attempts to locate the "Alfa-Rex" shell (/admin/alfa-rex.php, /wp-content/plugins/alfa-rex.php) and other malicious scripts (/hehe.php, /identity.php).
WordPress Obfuscation: Hunting for typosquatted or hidden configuration files like /wp-includes/style-engine/wp-conflg.php (misspelled 'config') and scripts hidden in /wp-includes/assets/.
SSL/Certificate Reconnaissance: Probing sensitive hidden directories like /.well-known/acme-challenge/ and /.well-known/install.php.
Administrative Targeting: Scanning for wp-trackback.php and link-add.php to identify potential exploit vectors in legacy WordPress features.
Frequency: High-density burst (18 requests/sec)
show less
Automated vulnerability scanner and backdoor hunting activity originating from Microsoft Azure infra ...
show moreAutomated vulnerability scanner and backdoor hunting activity originating from Microsoft Azure infrastructure. The actor is systematically probing the cpcontacts subdomain for known web shells and malicious PHP scripts, specifically targeting the "Ultimate VC Addons" plugin and WordPress core directories.
Observed Activity:
Exploit/Shell Hunting: Probing for the "Alfa-Rex" web shell: /wp-content/plugins/Ultimate_VC_Addons/assets/alfa-rex.php7.
Backdoor Probing: Searching for common malicious filenames: /ioxi-o.php, /0x.php, /akc.php, and /abcd.php.
Infrastructure Targeting: Scanning WordPress core directories for unauthorized PHP scripts: /wp-content/uploads/admin.php, /wp-fclass.php, and /wp-content/upgrade/index.php.
Frequency: High-velocity burst (17 requests within a single second), characteristic of a bot-driven exploit kit.
Intent: Identifying Remote Code Execution (RCE) entry points or existing server compromises.
show less
Aggressive vulnerability scanning and directory traversal targeting the autodiscover subdomain. The ...
show moreAggressive vulnerability scanning and directory traversal targeting the autodiscover subdomain. The actor is systematically probing for common backdoors and WordPress-specific vulnerabilities, specifically hunting for obfuscated shells in unusual core directories.
Observed Activity:
Shell Hunting: Targeted requests for malicious PHP scripts: /0x.php, /222.php, and various "about.php" scripts hidden in libraries like /wp-includes/Requests/.
Infrastructure Probing: Scanning for sensitive admin paths and controller extensions: /admin/controller/extension/extension/ and /wp-content/upgrade/index.php.
Bypass Attempts: Hunting for misconfigured WordPress login entry points in non-standard locations: /wp-includes/images/wp-login.php.
Frequency: High-density automated burst (25 requests in a single second), indicative of a bot-driven exploit scanner.
Intent: Identifying Remote Code Execution (RCE) entry points or existing server compromises.
show less
Aggressive vulnerability scanning and backdoor hunting originating from a Microsoft Azure IP. The ac ...
show moreAggressive vulnerability scanning and backdoor hunting originating from a Microsoft Azure IP. The actor is systematically probing the webdisk subdomain for known web shells and malicious PHP scripts, specifically targeting WordPress core and plugin directories.
Observed Activity:
Known Web Shell Hunting: Probing for specialized malicious scripts like /wp-includes/Requests/alfa-rex.php (Alfa Shell), /ioxi-o.php, /sx.php, and /akc.php.
WordPress Infrastructure Targeting: Scanning for unauthorized files in core paths: /wp-content/upgrade/index.php, /wp-fclass.php, and /wp-content/uploads/admin.php.
Plugin/Theme Probing: Attempting to access specific plugin-related paths like /wp-content/plugins/yanierin/akc.php and hunting for "about.php" shells within the Requests library.
Method: High-frequency automated HTTP GET requests (18+ requests in a single second), indicative of a bot-driven exploit scanner.
Intent: Identifying Remote Code Execution (RCE) entry points or existing server compromises.
show less
Persistent and aggressive automated vulnerability scanning detected. The source is performing exhaus ...
show morePersistent and aggressive automated vulnerability scanning detected. The source is performing exhaustive probing for web shells, backdoors, and WordPress core vulnerabilities across multiple subdomains.
Observed Activity:
Backdoor/Shell Hunting: Systematic requests for malicious scripts: /bolt.php, /fff.php, /rip.php, /ioxi-o.php, and /ff1.php.
WordPress Core Exploitation: Probing for unauthorized PHP files in sensitive directories: /wp-admin/css/bolt.php, /wp-content/themes/admin.php, /wp-content/uploads/admin.php, and /wp-act.php.
Directory Traversal/Reconnaissance: Scanning obscured paths such as /.trash7206/index.php, /.well-known/logs233/index.php, and /update/da222.php.
Frequency: Extremely high density (over 30 requests in a single second at 10:54:04 AM), indicating a high-concurrency automated exploit tool.
Intent: Identifying Remote Code Execution (RCE) entry points and exploiting misconfigured WordPress installations.
show less
Aggressive automated vulnerability scanning and web shell hunting originating from an Azure-hosted I ...
show moreAggressive automated vulnerability scanning and web shell hunting originating from an Azure-hosted IP. The actor is targeting administrative and infrastructure subdomains (cpcalendars., cpanel.) to locate common backdoors and exploit WordPress directory vulnerabilities.
Observed Activity:
Backdoor & Shell Hunting: Probing for malicious scripts including /bolt.php, /fff.php, /ff1.php, /ioxi-o.php, and /xmr.php.
WordPress Path Exploitation: Systematically scanning for unauthorized admin scripts in core folders: /wp-content/uploads/admin.php, /wp-admin/css/bolt.php, and /wp-content/themes/haha.php.
Administrative Reconnaissance: Attempting to access sensitive directories such as /wp-admin/maint/, /wk/, and obscured paths like /.well-known/logs233/.
Method: High-speed automated HTTP GET requests targeting common exploit kits and misconfigured upload directories.
Frequency: Sustained attacks occurring across different time blocks on March 12, indicating an persistent, automated botnet scanner.
show less
Web App Attack
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.